drughub[.]org[.]uk
“DrugHub Market - Official XMR Only Darknet Marketplace | PGP Login System”
drughub.org.uk — Não verificado. Tipo de golpe: Credential Phishing. Resumo das evidências: VirusTotal 3/91 (CRDF, Gridinsoft, SOCRadar); PhishDestroy score 76/100. Registrador: Namecheap.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain drughub.org.uk was registered on 13 January 2026 through Namecheap, Inc. t/a Spaceship and resolves to the IP address 188.114.97.3, which is hosted by CloudFlare, Inc. in Canada. The site presents a page titled “DrugHub Market - Official XMR Only Darknet Marketplace | PGP Login System” and returns HTTP status 200, indicating the page is actively serving content. TLS is provided by a Google Trust Services / WE1 certificate, confirming the use of a valid SSL chain. The same IP appears in a single AlienVault OTX pulse and is listed on one security blocklist. PhishDestroy currently blocks the domain, while Gridinsoft assigns a trust score of 0 out of 100, reflecting extreme malicious confidence. VirusTotal has not flagged any of the 95 files associated with the domain, but the absence of detections does not imply benign intent. The combination of a darknet‑focused branding, Monero‑only payment references, and a PGP login interface aligns with known generic phishing tactics that harvest cryptocurrency credentials. The limited visibility—only one OTX pulse and a single blocklist entry—suggests the campaign may be in early stages or employing low‑profile hosting. Defenders should add drughub.org.uk and its resolving IP 188.114.97.3 to URL filtering and sinkhole rules, monitor DNS queries for the domain, and correlate any observed PGP login attempts with credential‑theft alerts. Continued surveillance of the IP for changes in hosting or additional payloads is advised, as well as sharing any new artifacts with relevant threat‑intel communities.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
Análise do VirusTotal
Análise da configuração do site
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo